×
Register Here to Apply for Jobs or Post Jobs. X

Information Governance Risk and Compliance Analyst

Job in New York, New York County, New York, 10261, USA
Listing for: Fried Frank Business Services Opportunities
Full Time position
Listed on 2026-09-26
Job specializations:
  • Security
    Information Security & Data Protection, Cybersecurity
Salary/Wage Range or Industry Benchmark: 110000 - 125000 USD Yearly USD 110000.00 125000.00 YEAR
Job Description & How to Apply Below
Location: New York

At Fried Frank, we’re a community of 800 lawyers and 500 business services professionals across New York, Washington, DC, London, Frankfurt, and Brussels. We advise leading corporations, investment funds, and financial institutions on high-stakes M&A, securities, regulatory matters, real estate, and litigation. Our culture is grounded in our core values — excellence, integrity and collaboration — and is designed to foster continuous learning, meaningful mentorship, and lasting professional growth.

We are firmly committed to pro bono service and social justice, building on a proud legacy in civil rights. Our inclusive talent strategy is a core part of our broader talent management efforts and we remain steadfast in fostering a workplace where everyone has the opportunity to grow, thrive, and become their best professional and personal selves. Our business services professionals are integral to the firm’s success, driving innovation, operational excellence and exceptional client service across all areas of the firm.

We offer competitive compensation and a comprehensive benefits package, including comprehensive medical coverage, retirement plans and health and wellness initiatives designed to support your personal and professional wellbeing. We welcome passionate, driven individuals to join us, and be part of a team where you’ll be supported, inspired and empowered to build an exceptional career.

Position Summary:

As an Information Governance (IG), Risk, and Compliance Analyst, you will test, evidence, and report on the controls behind the firm’s IG, risk, compliance, and information security programs. You will run recurring control audits, build the queries and scripts that generate the evidence, and produce the artifacts relied upon in client audits and internal assurance work.

Duties & Responsibilities:

Information Governance:
  • Develop IG policies and procedures, and translate them into enforceable technical configurations and measurable controls.
  • Maintain an auditable inventory of data assets across Microsoft 365 and other approved information repositories, capturing classification, ownership, location, and retention state.
Risk Management:
  • Contribute to enterprise-wide risk assessments, quantifying exposure from over provisioned access, stale data, and sensitive data sprawl from platform reporting rather than self-attestation.
  • Develop risk mitigation strategies and control requirements, and track findings and remediation to verified closure.
Compliance:
  • Support compliance with client contractual obligations (including outside counsel guidelines), regulations, and data protection laws by implementing and evidencing the corresponding controls.
  • Serve as technical respondent for client audits, security questionnaires, and regulatory inquiries, mapping requests to implemented controls and assembling the evidence; familiarity with control frameworks (ISO, SOC 2, NIST) helps, though the emphasis is technical testing over certification work.
Audit, Control Testing, and Evidence Collection:
  • Plan and execute recurring control audits across Microsoft 365, Entra , Active Directory, and approved information repositories, and maintain the audit calendar, evidence library, and exception record.
  • Collect evidence programmatically with Power Shell, Microsoft Graph, and KQL, querying audit trails across identity, mail, file, and endpoint platforms to show a control operated over a defined period.
  • Perform entitlement reviews and access recertification covering nested group membership, privileged roles, service and shared accounts, dormant objects, and broadly permissioned repositories.
  • Test control effectiveness rather than assuming it, validating classification and DLP detection, retention and disposition execution,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary